VulnSea

Daily digest

Monday 20 April 2026

A quiet day: only 20 new CVEs against a recent average of about 42. Of those, 5 high. agentscope was the most-affected vendor with 4.

20
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2026-6606High· 7.3
5mo ago

AgentScope vulnerable to Server-Side Request Forgery

AgentScope vulnerable to Server-Side Request Forgery

▾ Twilightagentscope · agentscopeEPSS 0.47%via OSV
CVE-2026-6605High· 7.3
5mo ago

AgentScope vulnerable to Server-Side Request Forgery

AgentScope vulnerable to Server-Side Request Forgery

▾ Twilightagentscope · agentscopeEPSS 0.51%via OSV
CVE-2026-6604High· 7.3
5mo ago

AgentScope vulnerable to Server-Side Request Forgery

AgentScope vulnerable to Server-Side Request Forgery

▾ Twilightagentscope · agentscopeEPSS 0.47%via OSV
CVE-2026-6603High· 7.3
5mo ago

AgentScope Vulnerable to Remote Code Injection

AgentScope Vulnerable to Remote Code Injection

▾ Twilightagentscope · agentscopeEPSS 0.52%via OSV
CVE-2026-6596High· 7.3
5mo ago

Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API

Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API

▾ Twilightlangflow-base · langflow-baseEPSS 0.47%via OSV
CVE-2026-6634Medium· 6.3
5mo ago

Memos has an Incorrect Privilege Assignment issue

Memos has an Incorrect Privilege Assignment issue

▾ Sunlitusememos · github.com/usememos/memosEPSS 0.35%via OSV
CVE-2026-6599Medium· 6.3
5mo ago

Langflow vulnerable to injection

Langflow vulnerable to injection

▾ Sunlitlangflow · langflowEPSS 0.39%via OSV
CVE-2026-6587Medium· 6.3
5mo ago

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the compo…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-41245Medium· 5.9
5mo ago

Junrar is an open source java RAR archive library

Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories wh…

▾ Sunlitjunrar_project · junrarEPSS 0.53%via NVD
CVE-2026-6608Medium· 5.3
5mo ago

FastChat has a Content Moderation Bypass via Arena Side-by-Side Views

FastChat has a Content Moderation Bypass via Arena Side-by-Side Views

▾ Sunlitfschat · fschatEPSS 0.51%via OSV
CVE-2026-6607Medium· 5.3
5mo ago

FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)

FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)

▾ Sunlitfschat · fschatEPSS 0.74%via OSV
CVE-2025-66335Medium· 5.3
5mo ago

Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization

Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization

▾ Sunlitdoris-mcp-server · doris-mcp-serverEPSS 0.66%via OSV

Most-affected vendors

By CVEs published in the period.